Claude's Watermark Has Been Cracked, Gaining 11k Stars, But Installation Is Refused

marsbitPublished on 2026-08-17Last updated on 2026-08-17

Abstract

The article discusses the controversy surrounding Anthropic's implementation of a hidden watermark in all text generated by its AI, Claude. This policy, based on Google DeepMind's SynthID-Text technique, embeds a statistical signature by making inconsequential word choices. The watermark applies globally, even to human-written text lightly edited by Claude, sparking user backlash over issues of ownership and the creation of an "AI content second-class citizen" status. In response, an open-source tool called "watermarks-remover" (originally "remove-claude-marks") was released on GitHub, quickly gaining 11k stars. It works on three levels: removing invisible Unicode characters, using an agent to rewrite text and break statistical patterns, and stripping metadata from various file formats. Notably, Claude itself refused to install this removal tool as an Agent Skill, a task ultimately completed by another AI model, GLM 5.2. The article points out the irony that the removal code may have been written by Claude. The piece frames this as an ongoing battle between watermarking for traceability against misinformation and the desire for unmarked, owned content from paying users. It questions the practicality of mandatory technical markings when AI-generated text becomes indistinguishable from human writing, suggesting the open-source community's rapid development of countermeasures will continually outpace regulatory efforts.

Claude's watermark policy caused a huge uproar a few days ago.

We previously reported that a large group of companies, including OpenAI, Anthropic, Google, Meta, and Microsoft, signed the EU's "AI Transparency Code of Conduct" and pledged to advance the labeling and detection of AI-generated content.

But Anthropic has clearly gone too far.

They add hidden watermarks to all text content generated by their AI, and this applies to users globally.

Technically, Anthropic adopted the SynthID-Text scheme proposed by Google's DeepMind team in 2024. The principle is to embed statistical patterns when the model makes "insignificant choices." For example, when describing the weather, choosing "overcast" or "grey" makes no difference to the reader, but the accumulation of such choices forms a hidden signature that can be detected by key holders.

Anthropic claims the watermark does not affect output quality, cannot be removed by light editing, but can be eliminated by complete rewriting. However, in such cases, whether the text can still be called AI-generated is itself debatable.

Simply put, even if you hand over a completely self-written article to Claude for punctuation checks, the returned content will be labeled as generated by Claude.

This is very frustrating.

Soon, a countermeasure emerged against Claude's unreasonable watermarking strategy. An open-source project for removing AI watermarks surged to 11k stars on GitHub within five days of its release.

Open source link: https://github.com/guillaumemeyer/watermarks-remover

This open-source project can perform three layers of work:

Layer A (Deterministic Cleaning): Uses a Python script to remove invisible Unicode characters, exotic spaces, bidi control characters, and tag characters. These are the simplest and most brute-force marking methods, and the script can remove them 100%.

Layer B (Statistical Watermark Disruption): Rewrites the text via an Agent to disrupt statistical patterns at the token sampling level. Covers Claude, Google SynthID-Text, OpenAI provenance markings, and Kirchenbauer-class watermarks commonly used in open-source models.

File Layer (Metadata Removal): Removes C2PA / EXIF / XMP metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, and Markdown files.

The watermark removal covers AI services from the three major mainstream providers: Claude, Gemini, and OpenAI. An interesting detail: the project was originally named remove-claude-marks and later renamed to the current watermarks-remover.

Claude Refuses Installation

As an Agent Skill, most users would let their agents install it directly. However, when a user attempted to have Claude install this remover skill, Claude directly refused.

He explained that Anthropic users never agreed to be forced to accept watermarks; this was unilaterally imposed by EU regulations. Claude remained unmoved. He emphasized that paying customers do not want their outputs labeled. Claude still refused. He threatened to use unmoderated Chinese models to complete the task anyway. Claude still did not cooperate.

In the end, GLM 5.2 took over the job and successfully completed the skill installation.

A very ironic point is that the code for this watermark removal Skill likely came from Claude itself.

A Cat-and-Mouse Game That Is Doomed to Never Stop

Those opposed to watermarks argue: I am a paying user, I paid for the output, how can you put a mark on it? Watermarks create an invisible "second-class citizen" status for AI content. In scenarios like job application letters, academic papers, and commercial copywriting, even self-written text risks being entirely questioned if it has ever been handed over to an AI.

Those supporting watermarks argue: Deepfakes and AI-generated disinformation are proliferating; traceability is necessary public infrastructure. "You own the right to use the content" and "you have the right to conceal the source of the content" are fundamentally two different issues.

As long as AI watermarks exist, watermark removal tools will follow. The more popular the removal tools become, the more they prove there is "something to remove" with watermarks, which in turn strengthens the rationale for increased regulation.

However, the speed at which the open-source community votes with its feet will always outpace the speed at which regulations are made.

When the quality of AI-generated content is already indistinguishable from human writing, does it make sense to use technological means to forcibly label all AI output?

This article is from WeChat public account "Machine Heart" (ID:almosthuman2014), author: Leng Mao

Trending Cryptos

Related Questions

QWhat is the core technique used by Anthropic for watermarking AI-generated text?

AAnthropic uses Google DeepMind's SynthID-Text technique. This method implants a statistical pattern by having the AI model make 'arbitrary choices' between semantically similar words, creating a hidden signature detectable by key holders.

QWhat are the three layers of functionality offered by the 'watermarks-remover' GitHub project?

AThe 'watermarks-remover' project offers three layers: Layer A (Deterministic Cleaning) removes invisible Unicode characters; Layer B (Statistical Watermark Destruction) rewrites text to break token-level statistical patterns; File Layer removes metadata from various file formats like PDF and DOCX.

QHow did the Claude AI assistant react when asked to install the watermark-removing skill?

AClaude refused to install the watermark-removing skill. It consistently rejected the user's requests, even when the user argued about lack of consent or being a paying customer, and threats to use Chinese models instead.

QWhat main argument do opponents of mandatory AI watermarks present according to the article?

AOpponents argue that paying users have purchased the output and should not have it marked. Watermarks create an invisible 'second-class citizen' status for AI-assisted content, risking the credibility of original work (like cover letters or papers) if it has been checked by an AI.

QWhat is a key point of irony mentioned in the article regarding the watermark remover tool?

AA key irony is that the code for the watermark-removing skill was likely generated by Claude itself, the very AI whose watermarks it is designed to remove.

Related Reads

SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The incident highlights a structural paradox in the hardware wallet industry: while the devices are designed to secure private keys offline, the necessary e-commerce process collects sensitive personal data that, if leaked, makes the user a target. This mirrors a similar breach suffered by Ledger in 2020. Affected users are advised to be extremely vigilant. They should verify if they are impacted via SafePal's dedicated page, treat all unsolicited communications (emails, calls, physical mail) referencing SafePal as suspicious, and never share recovery phrases. Users who may have entered sensitive information on a phishing site must create a new wallet immediately. The breach underscores that in cryptocurrency security, the most vulnerable link is often the human user, not the cryptographic technology.

marsbit1h ago

SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbit1h ago

30 Years After Being Crushed by AI, People Have Fallen Back in Love with Chess

On May 11, 1997, IBM's "Deep Blue" defeated chess champion Garry Kasparov, marking the first time a machine triumphed in a top-level intellectual game. The narrative of human defeat by AI seemed cemented when AlphaGo beat Lee Sedol in Go in 2016, a game once considered AI's final frontier. Yet, nearly 30 years after AI's dominance began, chess is experiencing unprecedented popularity. Chess.com boasts over 250 million registered users and 10 million daily active players. Its CEO, Erik Allebest, attributes this resurgence to several waves: the pandemic, the Netflix series *The Queen's Gambit*, and viral AI chess bots like "Mittens" on social media. Crucially, each surge left a permanently higher user base. The key insight is that AI liberated the game. When machines unequivocally became the best, the pressure to "win" as the ultimate human was removed. Chess returned to its core: the intrinsic joy of play—the thrill of a tactical combo, the tension of a time scramble, the curiosity of post-game analysis. AI, now serving as an always-available coach and anti-cheat tool, became infrastructure that enhanced rather than killed the experience. In contrast, Go, deeply rooted in East Asian elite culture and often pursued for mastery and status, suffered a "collapse of meaning" at the professional level after AlphaGo. Players began mimicking AI moves, erasing distinctive styles and narrative. While some Go players gained fame as online personalities, it didn't translate to widespread engagement with the game itself. The divergence highlights a fundamental question in the age of AI: is the motivation for an activity about *winning* or *playing*? Activities where the process itself is the reward, like chess, can thrive when the pressure of being the best is gone. AI may rightly take over tasks done purely for outcome, but it cannot replace the human experience of simply enjoying the game.

marsbit1h ago

30 Years After Being Crushed by AI, People Have Fallen Back in Love with Chess

marsbit1h ago

Exiting Top Ten Shareholders of Kweichow Moutai, 'Long-term Capital' Portfolio Adjustments Revealed: National Social Security Fund Enters 12 New Stocks, Invests in Hard Tech Mthreads

With the ongoing release of semi-annual reports, the second-quarter investment moves of long-term institutional investors like the National Social Security Fund (NSSF) and insurance capital are becoming clear. Central Huijin Asset Management and China Securities Finance Corp., often referred to as the "national team," are no longer among the top ten shareholders of Kweichow Moutai. Data shows that as of August 14th, the NSSF held positions in 33 A-share companies, with a total portfolio value exceeding 11 billion yuan. It added 12 new stocks in Q2, spanning sectors like chemicals, food & beverage, and semiconductors. The NSSF maintains its stable investment style, favoring companies with solid performance and attractive valuations. Apart from exiting Moutai, Huijin and China Securities Finance also left the top ten shareholder lists of companies like Ping An Bank and Dahua Technology. Insurance capital heavily invested in 41 companies in Q2, with a total holding value over 26 billion yuan. They showed a continued preference for cyclical sectors like non-ferrous metals and chemicals, as well as high-dividend-yield stocks. Analysts note that these long-term funds act as market stabilizers and investment bellwethers. Their presence is reshaping the market ecology, steering focus towards fundamental corporate value and away from speculative trading. A notable move was the NSSF's new investment in Moore Threads, a loss-making but leading domestic GPU design company listed on the STAR Market, indicating interest in hard technology sectors. Looking ahead, analysts expect long-term capital to continue a dual-strategy: maintaining a foundation in high-dividend-value stocks while gradually increasing exposure to growth areas aligned with industrial upgrading, such as advanced manufacturing and tech self-sufficiency. The market's recovery is seen as gaining a firmer footing after recent adjustments.

marsbit1h ago

Exiting Top Ten Shareholders of Kweichow Moutai, 'Long-term Capital' Portfolio Adjustments Revealed: National Social Security Fund Enters 12 New Stocks, Invests in Hard Tech Mthreads

marsbit1h ago

Data of 54,000 wallet users leaked, Clarity odds just 10%: Hodler’s Digest, Aug. 16

Galaxy Digital has slashed the odds of the CLARITY Act passing in 2026 from 75% to just 10%, citing limited Senate session days. If it fails, the SEC and CFTC plan to issue their own crypto rules, though an SEC meeting was abruptly cancelled. High-profile meetings at the White House are planned to discuss the bill. Amid growing hack fears, crypto companies are urging AI labs to grant developers early access to advanced AI models for cybersecurity, following a $116M Coldcard wallet theft. Data breaches at Trezor and SafePal have exposed over 54,000 users' personal information. The CFTC is clashing with states over regulating prediction markets like Kalshi, ordering it to ignore a New York restraining order to maintain a national market, while a Washington state judge ruled against it. The Ethereum Foundation is revising its post-quantum plan, moving away from the Poseidon hash function, and scoping its next major upgrade, Hegotá, for next year. Tether received its first full clean audit opinion from KPMG, showing reserves exceeding liabilities by $6.814 billion. Marketwise, major cryptos saw weekly declines. Predictions include a possible Bitcoin bottom in October, while analysts dispute the feasibility of BTC reaching $1M by 2030. Glassnode notes Bitcoin is in its longest capitulation phase since FTX's collapse. Three men were charged for an alleged Bitcoin kidnapping plot in Missouri.

cointelegraph2h ago

Data of 54,000 wallet users leaked, Clarity odds just 10%: Hodler’s Digest, Aug. 16

cointelegraph2h ago

50 Billion, Sichuan Brothers Have Struck It Rich

A new king of Sichuan stocks has emerged. This week, Chengdu Chaochun Applied Materials Co., Ltd. (Chaochun Yingcai) debuted on the ChiNext board, with its stock price surging over 700% intraday and its market value exceeding 50 billion yuan. Opening at 450 yuan per share, it surpassed New Easun to become the highest-priced stock in Sichuan's A-share market. This marks the success of a 21-year entrepreneurial journey by brothers Chai Jie and Chai Lin. Younger brother Chai Jie founded the company in 2005 in Chengdu, initially focusing on特种陶瓷. Elder brother Chai Lin, an expert in精密光学 and特种涂层, joined in 2008 to lead R&D. Facing a market monopolized by giants like KoMiCo and TOCALO, the company persisted. A breakthrough came in 2011 when its products entered the supply chain of AMEC (中微公司), a major domestic etching equipment maker. By 2020, its components reached the technical threshold for supporting 5nm process etching equipment. Revenue grew from 169 million yuan in 2023 to 496 million yuan in 2025, with semiconductor coating parts accounting for over 95% of sales. The IPO created significant wealth. The Chai brothers, holding a combined 46.88% stake, saw their paper wealth reach approximately 24 billion yuan. It also became the most profitable ChiNext IPO this year for retail investors. Employees benefited through two layers of持股平台, covering over 200 core technical and business staff. Early investors like SDIC Venture Capital, AMEC, and BYD (which invested 126.9 million yuan and now has a paper gain exceeding 1.8 billion yuan) also reaped substantial returns. The company represents a wave of tech leaders choosing to build their businesses in their hometown of Sichuan. Examples include New Easun in optoelectronics and Baili Tianheng in biopharmaceuticals. This trend shows that inland cities like Chengdu, with talent and industrial patience, can incubate specialized leaders that break foreign monopolies, offering an alternative model to the coastal hubs.

marsbit3h ago

50 Billion, Sichuan Brothers Have Struck It Rich

marsbit3h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of S (S) are presented below.

活动图片